- NestJS – Authorization and Roles
Role-based access with @Roles and a RolesGuard, and the harder half nobody shows: ownership. Why the role never comes from a request body, why a foreign resource returns 404 rather than 403, and why the route whose rules depend on the row deliberately has no @Roles decorator at all.
- iOS – Dependency Injection Without a Framework
A composition root — one initialiser that decides every concrete type the app runs with — instead of singletons scattered through it. Why a static shared is a testing problem before it is a design problem, injecting through the SwiftUI environment, and the constructor parameter that turns an ordering rule into a compiler guarantee.
- Terraform – Interview Questions
The questions Terraform interviews actually ask, answered the way you would say them out loud. What state is for, `count` versus `for_each`, how locking works, module versioning, what happens when someone changes something in the console, Terraform versus CloudFormation versus Ansible, and how you would recover a corrupted state file.
- TypeScript – Modules and Type-Only Imports
import type and why a bundler needs you to say it, verbatimModuleSyntax, and the reason the NestJS half of this app writes `.js` in an import that points at a `.ts` file. Module resolution in one page, declaration files, and what to do about a package that ships no types.
- NestJS – Authentication with JWT
Register and login end to end: bcrypt with a cost that is slow on purpose, what goes in a token and what must never, signing with @nestjs/jwt, and the two defences that keep a login form from confirming which addresses are registered — one message for every failure, and a dummy hash comparison so they take the same time.